How Should Organizations Secure Unpatchable Legacy Systems?
An organization disabled unneeded services and placed a firewall in front of a business-critical legacy system. Which of the following best describes the actions taken by the organization?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the distinction between native security hardening and alternative risk mitigation strategies, with candidates frequently confusing the tactical use of firewalls for strategic risk control.
This question evaluates how teams mitigate vulnerabilities in outdated infrastructure when standard patching is impossible. The community consensus firmly identifies these measures as compensating controls.
Candidates typically choose Segmentation because they fixate on the firewall's isolation function, failing to recognize that the overarching goal is compensating for the legacy system's inability to meet modern security standards.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Compensating Controls
Compensating controls are alternative security measures implemented when primary controls (such as software updates, vendor patches, or native feature configurations) are unavailable, impractical, or too costly. In this scenario, the organization is dealing with a business-critical legacy system, which inherently lacks modern security architectures or patch support.Why Option D is Correct
Disabling unneeded services directly reduces the attack surface, while placing a firewall in front of the system creates a hardened perimeter. As noted by multiple community members, the keyword 'legacy' signals that traditional remediation isn't feasible, making these technical adjustments classic examples of compensating controls designed to maintain operational continuity without compromising security posture. Community feedback consistently highlights that when a system cannot be natively secured, alternative controls become mandatory.Why Other Options Are Incorrect
- Exception: Refers to a formal policy waiver granted for a specific user or system, not a technical hardening action.
- Segmentation: While firewalls can enforce network segmentation, the question emphasizes risk mitigation for an unpatchable asset. Segmenting is a technique; compensating controls describe the overarching risk management strategy. Several users debated this, but the primary objective aligns with compensation rather than pure network architecture design.
- Risk Transfer: Involves shifting financial or legal liability to a third party (e.g., cyber insurance or cloud SLAs), which does not apply to internal hardening steps.
Exam Takeaway
Always map the scenario's constraint (legacy/unpatchable) to the appropriate risk treatment framework before selecting the technical mechanism.Official Reference
- NIST Special Publication 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- CompTIA Security+ SY0-701 Official Study Guide: Domain 4.0 - Risk Management
- https://csrc.nist.gov/pubs/sp/800-53/rev-5/final
Exam Strategy
When a question highlights outdated, unsupported, or unpatchable systems, prioritize compensating controls over native security features. Always analyze the root problem first (inherent vulnerability) before selecting the tactical solution (firewall/service reduction), as CompTIA frequently tests the distinction between implementation methods and risk management objectives.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →